Home Malware Programs Keyloggers XP Advanced Keylogger

XP Advanced Keylogger

Posted: March 28, 2006

XP Advanced Keylogger is a commercial PC surveillance application that tracks user activity, logs all keystrokes, takes periodic screenshots and records web sites visited. Gathered data can be sent to a configurable e-mail account or uploaded to a predefined FTP server. XP Advanced Keylogger is able to hide its running processes. The application must be manually installed. It runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 gdiplus.dll
    2 jmail.dll
    3 licensemanager.dll
    4 toolkeylogger.dll
    5 toolkeylogger.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesLicenseManager.RegCodeHKEY_LOCAL_MACHINESOFTWAREClassesLicenseManager.RegCode.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.ApplicationHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Application.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.BlockExeHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.BlockExe.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.ClipboardHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Clipboard.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.HotkeyHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Hotkey.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.KeyboardHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Keyboard.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.LogToFTPHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.LogToFTP.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.LogToMailHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.LogToMail.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.PasswordHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Password.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.ScreenHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.Screen.1HKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.TaskListHKEY_LOCAL_MACHINESOFTWAREClassesToolKeyloggerDLL.TaskList.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunXPAdvancedKeyloggerHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallXPAdvancedKeylogger_is1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}4C4AB6B2-4BC3-494A-9232-5001E0793AC4E27D817E-A07E-481D-B449-48F83D7A18F4C610B319-5EF8-4302-AC99-4580932A5957C080FFDA-6D65-4F98-BA30-89A340FC2C2CBA7A51FA-04F1-45CB-B493-36AD46950432B7385BC9-4857-471B-9E06-CF2807288633B44432C2-4D5C-4495-AC72-55A39917142CA9676C29-ED6E-4C33-9295-8BC13CD3947D60FB8D96-D4E9-461B-81A1-2356040B73E55388D0EE-ACE4-4C4D-8532-72F234399AEB17B307BE-B2EC-43E8-8605-5E1F257273B1
Loading...